diff options
author | Sven Vermeulen <sven.vermeulen@siphos.be> | 2012-04-05 20:48:26 +0200 |
---|---|---|
committer | Sven Vermeulen <sven.vermeulen@siphos.be> | 2012-04-05 20:48:26 +0200 |
commit | aa8b3763c5c94be4e0bce63547b89fc73065f667 (patch) | |
tree | 06947239c1ee5f3953943f82bb9ff9cb77cb556b | |
parent | Merge branch 'master' of git+ssh://git.overlays.gentoo.org/proj/hardened-docs (diff) | |
download | hardened-docs-aa8b3763c5c94be4e0bce63547b89fc73065f667.tar.gz hardened-docs-aa8b3763c5c94be4e0bce63547b89fc73065f667.tar.bz2 hardened-docs-aa8b3763c5c94be4e0bce63547b89fc73065f667.zip |
Add information on XDM and other support
-rw-r--r-- | xml/selinux-faq.xml | 34 |
1 files changed, 32 insertions, 2 deletions
diff --git a/xml/selinux-faq.xml b/xml/selinux-faq.xml index 62c2c28..965adca 100644 --- a/xml/selinux-faq.xml +++ b/xml/selinux-faq.xml @@ -17,8 +17,8 @@ The FAQ is a collection of solutions found on IRC, mailinglist, forums or elsewhere </abstract> -<version>20</version> -<date>2012-02-26</date> +<version>21</version> +<date>2012-04-05</date> <faqindex> <title>Questions</title> @@ -862,5 +862,35 @@ When enabled, enforcing mode cannot be disabled anymore (until you reboot). </body> </section> +<section id="xdm"> +<title>Logons through xdm (or similar) fail</title> +<body> + +<p> +If you log on through xdm, gdm, kdm, slim or any other graphical logon manager, +you might notice in permissive mode that your context is off, and in enforcing +mode that you just cannot log on. +</p> + +<p> +The reason of this is that PAM needs to be configured to include SELinux +awareness in your session handling: +</p> + +<pre caption="Updating pam setting for gdm"> +... +session required pam_loginuid.so +session optional pam_console.so +<i>session optional pam_selinux.so</i> +</pre> + +<p> +Replicate the calls towards <path>pam_selinux.so</path> in the various +<path>/etc/pam.d/gdm*</path> files (or similar depending on your graphical +logon manager). +</p> + +</body> +</section> </chapter> </guide> |